Law / Finland

Finland

European Union law applies in Finland Finland is a member state of the European Union, whose 37 researched instruments are listed on the European Union page, not here. The law of Finland, described on this page below, applies here too.

16 of 19 named instruments researched to a stage, across all six areas of law we track: 16 in force. As of 15 September 2026.

When they take effect16 of 16 carry a date. Earlier is before 2014.
Before 2014: 2 instruments (2 in force) earlier 2014: 0 instruments 2015: 1 instrument (1 in force) ’15 2016: 0 instruments 2017: 0 instruments 2018: 0 instruments 2019: 6 instruments (6 in force) 2020: 0 instruments ’20 2021: 0 instruments 2022: 0 instruments 2023: 3 instruments (3 in force) 2024: 0 instruments 2025: 2 instruments (2 in force) 2026: 2 instruments (2 in force) ’26 today

in forceenacted but not yet in forceproposedrepealed, withdrawn or blocked

  1. AI law 2
  2. Privacy law 6
  3. Scraping law 3
  4. Cybersecurity law 3
  5. Age gating law 1
  6. News aggregation law 1

Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page.

AI law2 instruments, 2 in force

Research summary (218 words)

The EU AI Act (Regulation (EU) 2024/1689) applies directly in Finland and is not restated here as Finnish law; its Article 5, 50, and 53 duties and the Digital Omnibus deferral are covered in the eu document.

Finland's own AI Act implementing statute, Laki eraiden tekoalyjarjestelmien valvonnasta (Act on the Supervision of Certain Artificial Intelligence Systems, 1377/2025), designates Traficom as the single point of contact under AI Act Article 70, splits high-risk market surveillance among sectoral authorities, and creates a Sanctions Board that decides administrative fines.

Separately, Rikoslaki (Criminal Code, 39/1889) Chapter 20, Section 19, as reformed in 2022, bans distributing an image depicting a child sexually where the image is realistic, a definition that reaches a wholly AI-generated or deepfake image with no real underlying depiction on the same footing as an actual photograph.

Hallintolaki (Administrative Procedure Act, 434/2003) Chapter 8b, added by Act 487/2023, gives Finnish public authorities a statutory basis for fully automated administrative decisions, but the chapter binds government administration alone and imposes no duty on a private developer or deployer, so it is not recorded here as an ai instrument.

The Ministry of Education and Culture's investigation into AI-generated deepfakes and the regulation of synthetic likeness, opened in 2025 with findings due September 2026, has produced no bill as of the date below.

AI governance

Laki eraiden tekoalyjarjestelmien valvonnasta, Act on the Supervision of Certain Artificial Intelligence Systems

Laki eraiden tekoalyjarjestelmien valvonnasta (1377/2025)Finlex, official consolidated Swedish-language text of Laki eraiden tekoalyjarjestelmien valvonnasta (1377/2025)

In force 9 months, effective 1 January 2026. Binds private bodies.

What this law does

The Act's administrative-fine mechanism, its main operative duty, reaches a provider, authorized representative, importer, distributor, or deployer of an AI system rather than a government body: Section 24 bars a fine against every named category of Finnish public authority. The Act supplements the EU AI Act within its Article 2 scope, but does not apply to the work of Parliament, the Parliamentary Ombudsman, or the Chancellor of Justice.

Section 6 designates Traficom (Transport- och kommunikationsverket) as the common contact point under AI Act Article 70, responsible for coordinating the authorities competent under this Act and reporting annually to the European Commission. Sections 3, 4, and 5 split market surveillance of high-risk AI systems, prohibited practices, and transparency obligations among named sectoral authorities.

Section 13 creates a Sanctions Board (Paafoljdsavgiftsnamnden) that decides an administrative fine under Sections 14 to 22 against a provider, authorized representative, importer, distributor, deployer, or notified body for breaching a duty under the AI Act.

Section 24 bars a fine against state authorities, state enterprises, municipal authorities, welfare regions, independent public-law institutions, parliamentary agencies, the Office of the President of the Republic, and the Evangelical Lutheran and Orthodox Churches in Finland and their parishes, against anyone already facing prosecution or a final conviction for the same act, and more than five years after the violation.

What it requires

AI prohibited practices

Rikoslaki Chapter 20, Distribution and Possession of an Image Depicting a Child Sexually, Including Realistic Depictions

Rikoslaki (39/1889) 20 luku 19-21 sec, as amended by 8.7.2022/723Finlex, official consolidated text of Rikoslaki (39/1889)

In force since 1 January 2023. Binds public and private bodies.

What this law does

Section 19 bans manufacturing, offering, or otherwise distributing an image depicting a child sexually where the image is based on an actual situation involving a real child, or where the image is realistic, meaning it deceptively resembles a photograph of a situation in which a child is depicted sexually even though no real child was involved, by a fine or imprisonment for at most two years; the realistic-depiction branch reaches a wholly AI-generated or synthetically altered image on the same footing as an actual photograph.

Section 20 raises the penalty to imprisonment for at least four months and at most six years for an aggravated case, including where the depicted child is especially young or the image also shows serious violence against the child. Section 21 separately punishes possessing such an image, or paying or otherwise arranging access to it, by a fine or imprisonment for at most two years.

A narrow exception in Section 19 excuses production or distribution that is justified by the image's informational character or its evident artistic value.

Note and primary source

Privacy law6 instruments, 6 in force

Research summary (114 words)

Finland's private-sector regime is the General Data Protection Regulation (GDPR) plus the Data Protection Act (Tietosuojalaki 1050/2018), which specifies and supplements the GDPR within its own scope rather than creating a separate substantive regime.

Distinctive national features, drawn from the Act's own English translation, include a digital age of consent set at 13 (Section 5), a collegial Sanctions Board of the Data Protection Ombudsman and Deputy Ombudsmen that decides administrative fines (Section 24) rather than a single official, and a journalistic and academic expression exemption (Section 27) that disapplies a named list of GDPR articles, including the cross-border transfer chapter, in that narrow context. As at 24 August 2026; later amendment to the Tietosuojalaki is not independently confirmed.

Breach notification

GDPR Articles 33-34, Breach Notification in Finland

Regulation (EU) 2016/679, Arts. 33-34Official Journal text, EUR-Lex, Regulation (EU) 2016/679

In force since 1 January 2019. Binds public and private bodies.

What this law does

A controller must notify the Data Protection Ombudsman without undue delay, and within 72 hours where feasible, after becoming aware of a personal data breach affecting a person in Finland, and must notify affected individuals without undue delay where the breach is likely to result in a high risk to their rights and freedoms. The Data Protection Act adds no separate national breach notification regime.

What it requires

Comprehensive regime

Data Protection Act (Tietosuojalaki)

Tietosuojalaki 1050/2018 (amendments up to 29/2024 included)Ministry of Justice, Finland, official English translation, current to amendments through Act 29/2024

In force since 1 January 2019. Binds public and private bodies.

What this law does

The Data Protection Act specifies and supplements the General Data Protection Regulation (GDPR) within the GDPR's own scope of application. Drawn from the Ministry of Justice's official English translation: Section 5 sets the digital age of consent for information society services at 13, the lower bound GDPR Article 8 permits.

Section 24 assigns GDPR Article 83 administrative fines to a collegial Sanctions Board made up of the Data Protection Ombudsman and at least two Deputy Ombudsmen, with a three-member quorum, rather than to a single official, and bars a fine against central government and several other public bodies.

Section 27 disapplies specified GDPR articles for processing performed solely for journalistic, academic, artistic or literary purposes, including Chapter V transfer rules where applying them would infringe freedom of expression.

What it requires

Cross border transfer

GDPR Chapter V, Cross-Border Transfer of Personal Data from Finland

Regulation (EU) 2016/679, Arts. 44-50; Tietosuojalaki 1050/2018 sec. 27Official Journal text, EUR-Lex, Regulation (EU) 2016/679

In force since 1 January 2019. Binds public and private bodies.

What this law does

Transferring personal data of a person in Finland outside the European Economic Area requires a European Commission adequacy decision, Standard Contractual Clauses, Binding Corporate Rules, or a narrow Article 49 derogation, backed by the Article 83(5) top fine tier.

Section 27 disapplies Articles 44 to 50 for processing performed solely for journalistic, academic, artistic or literary purposes where applying them would infringe freedom of expression or information; outside that narrow exemption no Finland-specific broadening or narrowing of Chapter V was found.

What it requires

Data subject rights

GDPR Article 22 and Data Protection Act Sections 33-34, Data Subject Rights in Finland

Regulation (EU) 2016/679, Arts. 15-22; Tietosuojalaki 1050/2018 secs. 21, 33-34Ministry of Justice, Finland, official English translation, Data Protection Act Sections 21, 33, 34

In force since 1 January 2019. Binds public and private bodies.

What this law does

General Data Protection Regulation (GDPR) Articles 15 to 21 apply, including Article 22's qualified right against a decision based solely on automated processing with legal or similarly significant effect. Data Protection Act Section 33 restricts the Article 13/14 information duty, and Section 34 restricts the Article 15 access right, both on national security, defence, public order, offence prevention, or tax and public finance supervisory grounds.

Section 21 gives a right to refer a complaint to the Data Protection Ombudsman, with a three-month handling deadline and a right of appeal to an administrative court if that deadline is missed.

What it requires

Enforcement supervision

GDPR Articles 82-83 and Data Protection Act Section 24, Enforcement in Finland

Regulation (EU) 2016/679, Arts. 82-83; Tietosuojalaki 1050/2018 sec. 24Ministry of Justice, Finland, official English translation, Data Protection Act Section 24

In force since 1 January 2019. Binds public and private bodies.

What this law does

The Data Protection Ombudsman is Finland's supervisory authority. Section 24 assigns a General Data Protection Regulation (GDPR) Article 83 administrative fine to a collegial Sanctions Board chaired by the Ombudsman with at least two Deputy Ombudsmen and a three-member quorum, carries a ten-year limitation period from the infringement and a five-year limitation on enforcing an already-imposed fine, and bars a fine against central government authorities, municipal authorities, and several other named public bodies.

GDPR Article 82 gives any person who suffered material or non-material damage a right to compensation from the controller or processor, enforceable in the ordinary Finnish courts.

What it requires

Sensitive categories

GDPR Article 9 and Data Protection Act Section 6, Special Categories in Finland

Regulation (EU) 2016/679, Art. 9; Tietosuojalaki 1050/2018 sec. 6Ministry of Justice, Finland, official English translation, Data Protection Act Section 6

In force since 1 January 2019. Binds public and private bodies.

What this law does

General Data Protection Regulation (GDPR) Article 9(1) classifies biometric data processed for unique identification as a special category.

Data Protection Act Section 6, read in full, lifts the Article 9(1) bar in eight named contexts (insurance claims, statutory duty, trade union membership for employment law, healthcare and social welfare delivery, anti-doping and disability sports, and research, statistics or archiving); none of the eight names biometric data, and the section carries no illustrative list or enumeration of biometric identifier types.

Biometric data processed for unique identification is therefore governed directly by GDPR Article 9 itself, with no Finland-specific narrowing or widening of the definition found.

What it requires

Scraping law3 instruments, 3 in force

Research summary (221 words)

Finland has no scraping-specific statute, so most dimensions are governed by general law.

Rikoslaki (Criminal Code, 39/1889) Chapter 38, Section 8 criminalizes unlawfully hacking into a computer system by using an access code that does not belong to the offender or by otherwise breaking a protective measure, or obtaining data from such a system by a special technical device without hacking into it; reading a public, unauthenticated page without defeating an access control falls outside a plain reading of that requirement, and no reported Finnish case construing that boundary for a scraper has been located.

No Finnish court decision on the enforceability of a browsewrap or clickwrap terms-of-service against a scraper has been located. The Data Protection Act and General Data Protection Regulation (GDPR), already researched under the privacy topic, govern the reach of personal-data law over scraped public personal data without a scraping-specific carve-out.

Tekijanoikeuslaki (Finland's Copyright Act) Section 13b permits reproducing a work for text-and-data-mining purposes, with an author opt-out for works generally and a broader, non-waivable exception for research organizations and cultural heritage institutions, and Section 49 confers a sui generis right on the maker of a database or collection requiring substantial investment.

No Finnish statute or reported case establishes a scraping-specific unfair-competition, misappropriation, or trespass doctrine, and none assigns particular legal weight to a robots.txt directive or to an AI-training-specific rule.

Computer misuse

Rikoslaki Chapter 38, Tietomurto and törkeä tietomurto (Computer Break-in and Aggravated Computer Break-in)

Rikoslaki (39/1889) 38 luku 8-8a sec, as amended by 10.4.2015/368Finlex, official consolidated text of Rikoslaki (39/1889)

In force since 4 September 2015. Binds public and private bodies.

What this law does

Section 8 punishes unlawfully hacking into a computer system where data is processed, stored, or transmitted electronically, or into a separately protected part of such a system, by using an access code that does not belong to the offender or by otherwise breaking a protective measure, and separately punishes obtaining data from such a system by a special technical device without hacking into it, both as a computer break-in (tietomurto) punishable by a fine or imprisonment for at most two years; the section applies only where a more severe penalty is not provided elsewhere.

Section 8a raises the penalty to a fine or imprisonment for at most three years for an aggravated computer break-in, committed as part of an organized criminal group or in a particularly methodical manner, where the offense is also aggravated when assessed as a whole.

What it requires

Cybersecurity law3 instruments, 3 in force

Research summary (461 words)

Finland transposed the NIS2 Directive (Directive (EU) 2022/2555) through the Kyberturvallisuuslaki (Cybersecurity Act, 124/2025), enacted 4 April 2025 and in force since 8 April 2025, consolidated with six amendments through 4 September 2026.

The Act binds a legal or natural person that carries out an Annex I or Annex II activity and meets or exceeds the medium-enterprise thresholds of Commission Recommendation 2003/361/EC, and, regardless of size, a provider of public electronic communications networks or services, a trust service provider, a top-level-domain registry operator, a DNS service provider, or a critical entity designated outside the public administration sector under the Act on Protecting and Improving the Resilience of Critical Infrastructure (310/2025).

Annex I's digital-infrastructure entry separately names a cloud computing service provider, a data-centre service provider and a content-delivery-network provider alongside the DNS and top-level-domain categories already named, and Annex II's digital-service-provider entry names an online marketplace, an online search engine and an online social-networking-platform provider, all supervised by Traficom together with transport and ICT service management.

The Act's own Section 1 carves the public administration sector named in NIS2 Annex I point 10 out of its scope, assigning that sector instead to the Act on Information Management in Public Administration (906/2019), a different Finnish instrument not researched here; a bound entity's risk-management and incident-notification duties, and their EUR 10,000,000 or 2 percent (essential entity) and EUR 7,000,000 or 1.4 percent (other bound entity) administrative-penalty bands, are researched on this jurisdiction's two Kyberturvallisuuslaki rows.

The wider Annex I and Annex II sector classes the Act designates (energy, gas and district heating or cooling alongside the transport, digital-infrastructure and ICT-service-management categories confirmed above, and the remaining NIS2 Annex I and II sectors) are a designation and sector class no activity in this vocabulary expresses, so only the digital-provider slice is flagged here.

Separately, Finland's Laki eräiden tuotteiden kyberkestävyydestä sekä kyberturvallisuussertifioinnista (439/2026, colloquially the Kyberkestävyyslaki), enacted 29 May 2026 and in force since 1 June 2026, supplements the directly applicable Cyber Resilience Act (Regulation (EU) 2024/2847) with national market-surveillance and enforcement machinery rather than restating its substantive requirements: it names Traficom as the Article 52 market surveillance authority, leaves a manufacturer's Article 14 vulnerability and incident-notification duty to the Regulation itself while directing the report to Finland's CSIRT unit, and sets Finland's own administrative-penalty amounts within the Regulation's Article 64 bands, from EUR 15,000,000 or 2.5 percent of worldwide turnover for a manufacturer's essential-requirements breach down to a flat EUR 100,000 for a cybersecurity-certification breach, researched on this jurisdiction's third row.

Finland has no general reasonable-security or information-security-programme statute with no sector gate; the closest general duty is General Data Protection Regulation (GDPR) Article 32's security-of-processing obligation and the Tietosuojalaki's breach-notification duties to the Data Protection Ombudsman, both of which sit in the privacy topic rather than here.

Product security requirements

Kyberkestävyyslaki, National Enforcement and Market Surveillance for the Cyber Resilience Act

Laki eräiden tuotteiden kyberkestävyydestä sekä kyberturvallisuussertifioinnista (439/2026), 1, 7-9, 15-16 ja 31-38 §Consolidated text

In force 4 months, effective 1 June 2026. Binds private bodies.

What this law does

The Laki eräiden tuotteiden kyberkestävyydestä sekä kyberturvallisuussertifioinnista (439/2026), known colloquially as the Kyberkestävyyslaki, specifies and supplements the directly applicable Cyber Resilience Act (Regulation (EU) 2024/2847) and its national application, rather than restating the Regulation's own essential cybersecurity requirements, which are documented at the European Union level and are not repeated here.

Section 7 leaves a manufacturer's duty to report an actively exploited vulnerability or a severe security-affecting incident entirely to Article 14 of the Regulation, adding only that the report goes to Finland's CSIRT unit, which must in turn notify the market surveillance authority under the Regulation's Article 16(3); Section 8 lets a manufacturer or other party voluntarily report a vulnerability, cyberthreat, incident or near miss to the CSIRT unit under Article 15, and information reported this way cannot be used against the reporter in a criminal investigation or an administrative decision without consent.

Section 15 names Liikenne- ja viestintävirasto (Traficom) as the Regulation's Article 52 market surveillance authority, except that Section 16 assigns a high-risk AI system within the Regulation's scope to the market surveillance authority the Act on the Supervision of Certain Artificial Intelligence Systems designates instead.

Chapter 6 sets Finland's own administrative penalty amounts within the bands Regulation Article 64 allows a Member State to set: up to EUR 15,000,000 or 2.5 percent of a manufacturer's worldwide turnover for breaching the essential cybersecurity requirements of Article 13 and Annex I Part I (Section 31, first paragraph); up to EUR 10,000,000 or 2 percent for a manufacturer's other obligations, or for an authorised representative's, importer's, distributor's or notified body's own obligations (Section 31 second paragraph and Sections 32 to 35); up to EUR 5,000,000 or 1 percent for other Regulation-related breaches, such as supplying incorrect or misleading information to a notified body or the market surveillance authority (Section 36); and a flat EUR 100,000 cap for a cybersecurity-certification breach (Section 37).

Finland's Act entered into force 1 June 2026, ahead of the Regulation's own Article 14 reporting duty, which applies from 11 September 2026.

What it requires

Sector security regimes

Kyberturvallisuuslaki, Cybersecurity Risk-Management Measures and Governance

Kyberturvallisuuslaki (124/2025), 3 ja 7-10 §Consolidated text, Finlex, Kyberturvallisuuslaki 124/2025, version in force from 8 April 2025, amendments through 4 September 2026

In force since 8 April 2025. Binds public and private bodies.

What this law does

Sections 7 to 10 of the Kyberturvallisuuslaki require an entity within scope to identify, assess and manage the risks to the network and information systems it uses in its operations or to provide its services, and to act to prevent or minimise an incident's impact on its operations, their continuity, the recipients of its services and other services (Section 7).

The entity must maintain a documented cybersecurity risk-management operating model (Section 8) whose management measures cover, at minimum, twelve areas matching NIS2 Article 21(2): risk-management policy and effectiveness assessment; network and information system security policy; supply-chain security, including vulnerability handling and disclosure for direct suppliers and service providers; asset management and identification of security-critical functions; personnel security and cybersecurity training; access-control and authentication procedures; cryptography policy; incident detection and handling; backup, recovery planning, crisis management and business continuity; basic cyber-hygiene practices; and, where appropriate, multi-factor or continuous authentication (Section 9).

The entity's board, supervisory board or chief executive is responsible for organising the implementation and oversight of this risk management, approves the operating model, and must hold sufficient familiarity with cybersecurity risk management (Section 10).

Liikenne- ja viestintävirasto (Traficom) is the supervisory authority for Annex I items 1 to 7, covering transport, digital infrastructure and ICT service management, and for Annex II items 1 to 5, covering postal and courier services and the online marketplace, online search engine and online social-networking-platform digital-service-providers flagged here; the Act designates seven further sector authorities for its other Annex I and II classes.

An intentional or grossly negligent failure of the Section 7, 8 or 9 duties is subject to an administrative penalty of up to EUR 10,000,000 or 2 percent of worldwide annual turnover for an essential entity and up to EUR 7,000,000 or 1.4 percent for any other bound entity (Section 38), mirroring NIS2 Article 34(4) and (5), though Section 35 exempts state authorities, state enterprises, wellbeing regions and joint authorities, municipal authorities, independent public-law institutions, parliamentary agencies, the Office of the President, and the Evangelical Lutheran and Orthodox Churches of Finland and their parishes from the penalty itself, without exempting them from the underlying duty.

Beyond the entities that meet or exceed the medium-enterprise thresholds of Commission Recommendation 2003/361/EC while carrying out an Annex I or Annex II activity, Section 3 binds a narrower set of entities regardless of size: a provider of public electronic communications networks or publicly available electronic communications services, a trust service provider, a top-level-domain registry operator, a DNS service provider, and a critical entity designated outside the public administration sector under the Act on Protecting and Improving the Resilience of Critical Infrastructure (310/2025).

Section 1 excludes the public administration sector named in NIS2 Annex I point 10 from this Act's own scope, assigning that sector instead to the Act on Information Management in Public Administration (906/2019), a different Finnish instrument not researched here.

What it requires

Vulnerability and incident reporting

Kyberturvallisuuslaki, Significant-Incident Reporting Obligations

Kyberturvallisuuslaki (124/2025), 11-14 ja 22 §Consolidated text, Finlex, Kyberturvallisuuslaki 124/2025, version in force from 8 April 2025, amendments through 4 September 2026

In force since 8 April 2025. Binds public and private bodies.

What this law does

Sections 11 to 14 of the Kyberturvallisuuslaki require a bound entity to notify its supervisory authority without delay of a significant incident, defined as one that has caused or could cause a serious service disruption or considerable financial loss to the entity, or that has affected or could affect another natural or legal person with considerable material or immaterial damage.

An early notification is due within 24 hours of detecting the significant incident and a follow-up notification within 72 hours of detection, both clocks running from the moment of detection rather than from each other (Section 11). A trust service provider whose trust services are affected must instead file its follow-up notification within 24 hours rather than 72 (Section 11).

An interim report is due on the supervisory authority's request, or within one month of the follow-up notification if the incident is long-running (Section 12), and a final report is due within one month of the follow-up notification, or within one month of the incident's resolution if it is still ongoing at that point, describing the incident, its likely root cause, mitigation measures taken and any cross-border effects (Section 13).

Where a significant incident is likely to adversely affect an entity's service, or a significant cyberthreat may affect the recipients of that service, the entity must notify them without delay of the incident, the threat, and available countermeasures (Section 14).

Separately, Section 22 makes the Act's CSIRT unit, not the affected manufacturer or provider, the NIS2 Article 12 coordinator for coordinated vulnerability disclosure: it receives reports of vulnerabilities, which may be submitted anonymously, and handles the necessary follow-up. The same penalty bands and exemptions described on this jurisdiction's companion risk-management row apply to a failure of the Section 11, 12 or 13 reporting duties.

What it requires

Age gating law1 instrument, 1 in force

Research summary (120 words)

Laki kuvaohjelmista (Act on Audiovisual Programmes, 710/2011) requires a provider to classify an audiovisual programme by age limit before offering it, or to mark plainly that an unclassified programme is restricted to those 18 and older, and it obliges the provider to keep an age-restricted programme from being watched by an underage viewer through broadcast timing, a blocking service, or otherwise verifying age when the programme is offered.

The Kansallinen audiovisuaalinen instituutti (National Audiovisual Institute, KAVI) supervises compliance. No Finnish statute imposing an age-verification duty on a social media platform, an app store, or a design-code style duty on a service likely to be accessed by children has been located; those three families remain unresearched as of the date below.

Adult content age verification (AV)

Laki kuvaohjelmista, Audiovisual-Programme Classification, Age-Limit Marking and Minor-Access Duties

Laki kuvaohjelmista (710/2011), as amended, secs. 2, 5, 6, 16, 36Finlex, official consolidated text of Laki kuvaohjelmista (710/2011)

In force since 1 January 2012. Binds public and private bodies.

What this law does

Section 5 lets a provider offer an audiovisual programme only if it carries a clearly visible age-limit and content mark under Section 16, or, for a programme unambiguously intended only for those 18 and older, a clear mark of the 18-year age limit alone. Section 16 requires a programme harmful to a child's development to be classified 7, 12, 16, or 18 years with a content symbol, and lets a programme intended solely for adults skip classification if it instead carries the 18-year mark.

Section 6 prohibits offering a programme rated 18 to a minor at all, subject to a broadcast-timing exception. The same section requires the provider to keep a programme rated 7, 12, or 16 from being watched by a younger child through broadcast timing, making a blocking service available, or otherwise verifying age when the programme is offered. The National Audiovisual Institute supervises compliance and maintains the public register of classified programmes under Sections 17 and 18.

Note and primary source

News aggregation law1 instrument, 1 in force

Research summary (96 words)

Tekijanoikeuslaki (Finland's Copyright Act) Section 50, added by Act 263/2023 transposing Digital Single Market (DSM) Directive Article 15, gives the publisher of a press publication the exclusive right to reproduce it and communicate it to the public for a commercial purpose, for two years from the end of the year the press publication was published; the right does not reach an individual user's private or non-commercial use, a hyperlink, or an individual word or a very short extract.

No compelled platform-to-publisher bargaining regime, hot-news misappropriation doctrine, or reported case addressing hyperlinking or framing under Finnish law has been located.

This page covers the instruments LexLint has researched to a stage. Instruments named in the corpus but not yet researched are counted in the head and are not listed here. Every entry carries its own primary source on its note page. This is a research index, not legal advice.